Lesson 4 of 5 · 5 min · ends with a checkpoint

Data discipline

Why hygiene matters — including selfishly

Module 2 covered hygiene as a forecasting requirement. Here are the four reasons that actually motivate people, in ascending order of self-interest. Forecast accuracy: hiring, cash and board guidance are computed from fields reps typed, and a pipeline that flatters is worse than none because the company acts on it. Territory fairness: territories, account assignments and inbound routing are built from CRM data, so under-recorded accounts look under-worked and the next carve-up will not go your way. Your own commission: disputes are settled from the record — who owned it, when it was created, what it was worth, new business or expansion — not from your recollection. Continuity: the CRM is the only thing standing between your customer and explaining their situation from scratch to a stranger.

Single source of truth means one system holds the authoritative version and, where systems disagree, that one wins. In practice it demands that records are created in the CRM rather than copied to it later, that integrations write back rather than fork, and that nobody keeps a private parallel pipeline. If the CRM genuinely lacks a view you need, build a report or ask the admin — do not start a private copy of the company's most important asset.

UK data protection for B2B prospecting

Two regimes apply, and confusing them is the common mistake. UK GDPR governs personal data — information about an identified or identifiable living person. A named individual's work email, direct dial and job title are personal data; a generic info@ address for a limited company is not. PECR — the Privacy and Electronic Communications Regulations — governs electronic marketing specifically: emails, texts, live and automated calls. PECR sits on top of UK GDPR and you must satisfy both.

The PECR subscriber distinction. PECR separates corporate subscribers — organisations with their own legal personality, such as limited companies, LLPs and Scottish partnerships — from individual subscribers, which includes people, sole traders and ordinary (unincorporated) partnerships. The rule requiring consent or a "soft opt-in" for unsolicited marketing email applies to individual subscribers. It does not apply to corporate subscribers, which is why cold B2B email to a limited company is lawful in the UK in a way cold B2C email generally is not.

Two things that exemption does not excuse. You must not conceal your identity, and you must provide a valid address for opt-out requests — that covers marketing by electronic mail generally, corporate recipients included. And UK GDPR still applies whenever the recipient is a named individual.

Live calls. Screen against both the TPS (Telephone Preference Service) and the CTPS (Corporate Telephone Preference Service), plus your own do-not-call list, and do not call a registered number without consent. Identify yourself and your organisation, allow your number (or an alternative contact number) to be displayed rather than withholding it, and give contact details on request. Screening is not a one-off — registers change, so lists are re-screened on a cycle.

Legitimate interests, properly understood. For B2B prospecting the usual lawful basis under UK GDPR is legitimate interests. It is not a magic word: it requires a documented three-part test — a genuine purpose, necessity, and a balance that does not override the individual's interests and reasonable expectations. Marketing to a relevant professional's work address about something connected to their job passes comfortably; scraping a personal mobile and texting it does not.

Transparency. Where personal data comes from somewhere other than the person — a data vendor, a website, a scrape — UK GDPR requires you to tell them what you hold, where it came from, why, and their rights, generally within a month or at first contact. This is why serious B2B data vendors run notification programmes, and it is a fair question to ask before your company buys a list.

The right to object is absolute. For direct marketing there is no balancing test at the objection stage: you stop, and their details go on a suppression list — keeping just enough data to remember not to contact them. Opt-outs are honoured immediately, across every channel and tool, and never quietly reset when a sequence is rebuilt.

Things you must not do, plainly: ignore, delay or lose an opt-out, or "clean" a suppression list by deleting it; keep an unmanaged personal spreadsheet or export of prospect data outside employer-controlled systems, including on a personal device and especially when you leave a job (taking a customer list with you is both a breach and, in most contracts, a disciplinary matter); use a bought list without asking where it came from and what people were told; disguise marketing as a "research survey" or a service call; keep personal data indefinitely in case it is useful; or put special-category data anywhere near a sales CRM. That last one bites in health tech: patient data, clinical data about identifiable individuals, or anything a customer shares in confidence about their own patients has no business in an opportunity record. If a customer sends you something like that, escalate it internally rather than filing it.

And the teeth got sharper. PECR breaches were historically capped at £500,000. The Data (Use and Access) Act 2025 raised the maximum to UK GDPR levels — up to £17.5 million or 4% of global annual turnover — with the bulk of the Act's provisions commencing in 2026. That turned marketing compliance from a nuisance-fine risk into a board-level one.

Voice from the field

"AFK made calls to those registered with the Telephone Preference Service, and failed to keep proper records of consent for those it was calling as well as failing to properly disclose to people what they would be consenting to."
— Andy Curry, Interim Director of Enforcement and Investigations, Information Commissioner's Office, on a £90,000 PECR penalty (April 2025)

Note what the regulator objected to: not the calling, but the absence of records, the failure to screen, and the failure to tell people plainly what they were agreeing to. Three record-keeping failures. Compliance in prospecting is overwhelmingly a documentation discipline — which is why the CRM habit and the legal habit turn out to be the same habit.

Field note

Nobody expects an AE candidate to be a data protection specialist, and pretending to be one is a poor trade. What lands is proportionate awareness: that UK GDPR and PECR are different regimes, that B2B email to corporate subscribers sits differently from B2C, that calls are screened against TPS and CTPS, that legitimate interests needs a documented assessment rather than an assertion, and that an opt-out is honoured immediately everywhere. Then the sentence that actually reassures a hiring manager: "and anything genuinely borderline, I'd take to whoever owns compliance rather than decide alone."

Checkpoint 4 · answer to continue reading
Question 1 of 3
Under PECR, which of these is treated as a corporate subscriber?